VulnerabilityModified
CVE-2023-37629
Online Piggery Management System 1.0 is vulnerable to File Upload.
CRITICAL 9.8EPSS 23.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 23.31% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- simple online piggery management system project/simple online piggery management system
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/173656/Online-Piggery-Management-System-1.0-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/1337kid/Piggery_CMS_multiple_vulns_PoC/tree/main/CVE-2023-37629Exploit, Third Party Advisory
- https://www.sourcecodester.com/php/11814/online-pig-management-system-basic-free-version.htmlProduct
- http://packetstormsecurity.com/files/173656/Online-Piggery-Management-System-1.0-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/1337kid/Piggery_CMS_multiple_vulns_PoC/tree/main/CVE-2023-37629Exploit, Third Party Advisory
- https://www.sourcecodester.com/php/11814/online-pig-management-system-basic-free-version.htmlProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.